[Bug 736694] New: After zypper dup: apparmor prevents named from starting
https://bugzilla.novell.com/show_bug.cgi?id=736694 https://bugzilla.novell.com/show_bug.cgi?id=736694#c0 Summary: After zypper dup: apparmor prevents named from starting Classification: openSUSE Product: openSUSE 12.1 Version: Final Platform: Other OS/Version: Other Status: NEW Severity: Major Priority: P5 - None Component: AppArmor AssignedTo: suse-beta@cboltz.de ReportedBy: kkaempf@suse.com QAContact: qa@suse.de Found By: Development Blocker: --- Dec 14 08:43:11 heron named[5401]: starting BIND 9.8.1-P1 -t /var/lib/named -u named Dec 14 08:43:11 heron named[5401]: built with '--prefix=/usr' '--bindir=/usr/bin' '--sbindir=/usr/sbin' '--sysconfdir=/etc' '--localstatedir=/var' '--libdir=/usr/lib64' '- -includedir=/usr/include/bind' '--mandir=/usr/share/man' '--infodir=/usr/share/info' '--with-openssl' '--enable-threads' '--with-libtool' '--enable-runidn' '--with-libxml2 ' '--with-dlz-mysql' '--with-dlz-ldap' 'CFLAGS=-fmessage-length=0 -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector -funwind-tables -fasynchronous-unwind-tables -g -DNO_VERS ION_DATE -fno-strict-aliasing' 'LDFLAGS=-L/usr/lib64' Dec 14 08:43:11 heron named[5401]: adjusted limit on open files from 4096 to 1048576 Dec 14 08:43:11 heron named[5401]: found 4 CPUs, using 4 worker threads Dec 14 08:43:11 heron named[5401]: using up to 4096 sockets Dec 14 08:43:11 heron named[5401]: initializing DST: openssl failure Dec 14 08:43:11 heron named[5401]: exiting (due to fatal error) Dec 14 08:43:11 heron kernel: [ 174.231525] type=1400 audit(1323848591.441:32): apparmor="DENIED" operation="file_mmap" parent=5400 profile="/usr/sbin/named" name="/var/lib/named/lib64/engines/libgost.so" pid=5401 comm="named" requested_mask="m" denied_mask="m" fsuid=44 ouid=0 -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=736694 https://bugzilla.novell.com/show_bug.cgi?id=736694#c1 --- Comment #1 from Klaus Kämpf <kkaempf@suse.com> 2011-12-14 08:13:59 UTC --- Workaround for this one: zypper rm *apparmor* -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=736694 https://bugzilla.novell.com/show_bug.cgi?id=736694#c2 Christian Boltz <suse-beta@cboltz.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED Resolution| |DUPLICATE --- Comment #2 from Christian Boltz <suse-beta@cboltz.de> 2011-12-14 23:36:21 CET --- That's a very bad workaround ;-) The correct workaround is to update the profile using aa-logprof or in this case using the proposed fix from bug 731572#c0. It's not the most secure solution IMHO, but it's OK for now and will work. Even if it's a known issue: thanks for reporting it! *** This bug has been marked as a duplicate of bug 731572 *** http://bugzilla.novell.com/show_bug.cgi?id=731572 -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com